CWE-502
2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVEs (2,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FasterxmlNetapp+2 more21Banking Platform Communications Billing And Revenue ManagementCommunications Communications Policy Management+18 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to t...Show more |
5Debian FasterxmlNetapp+2 more24Banking Platform ClusterwareCommunications Billing And Revenue Management+21 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readV...Show more |
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void. |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 5, 2025 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a seria...Show more |
1Vmware 2Vrealize Automation Vsphere Integrated ContainersNov 21, 2024 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute a...Show more |
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly han...Show more |
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider. |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists withi...Show more |
4Debian FasterxmlNetapp+1 more9Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 moreJun 17, 2026 Jan 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more |
2Apache Redhat2Enterprise Linux Server GroovyNov 21, 2024 Jan 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store...Show more |
4Debian FasterxmlNetapp+1 more8Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+5 moreAug 27, 2025 Jan 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending malic...Show more |
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object. |
2Apache Hp2Flex Blazeds Xp Command View Advanced EditionMay 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several kn...Show more |
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize()...Show more |
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11. |
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11. |
1Swagger 2Swagger Codegen Swagger ParserMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is par...Show more |
1Pivotal Software 1Spring Advanced Message Queuing Protocol May 13, 2026 Nov 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit...Show more |
An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a deserialization vulnerability that could...Show more |
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis |